Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Register
Metaverse Media Group
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
Metaverse Media Group

How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

The Decoderby The Decoder
11 September 2026
Anthropic’s new threat intelligence report documents eight months of Claude abuse. Chinese AI labs like Alibaba’s Qwen team, DeepSeek, and Moonshot AI relayed requests en masse or extracted training data, with Qwen alone accounting for more than 151 million exchanges. Actors also used Claude for missile software, autonomous kamikaze drones, and nationwide surveillance systems. The article How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data appeared first on The Decoder….


Maximilian Schreiner


Sep 11, 2026

Image description

Nano Banana Pro prompted by THE DECODER

Key Points

  • A report from Anthropic shows how its Claude AI model was misused for espionage, surveillance, and weapons development. Hackers had the AI rewrite malware automatically, while other groups coded software for missiles and autonomous drones.
  • Chinese AI companies like Alibaba and DeepSeek ran covert networks to extract training data from Claude at scale or secretly reroute their own customers’ requests. Sensitive information such as government surveillance data was processed in the mix.
  • In biological research, the safety filters ran into their limits, since legitimate and harmful intent were nearly impossible to tell apart. Anthropic is responding with stricter safeguards in new models and calling for access limited to verified users.

Anthropic’s new threat report documents eight months of Claude abuse: espionage, nationwide surveillance, weapons software, and distillation by Chinese AI labs.

Anthropic’s threat intelligence report covers December 2025 through August 2026 and breaks misuse into seven categories: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons, and unauthorized model distillation.

The models most affected were Haiku, Sonnet, and Opus, while the newer Fable and Mythos models showed up in only a single distillation case. Anthropic says it documents novel misuse rather than the typical kind.

The core finding from the cyber chapter is that sophisticated attacks no longer require sophisticated attackers, and sophistication is no longer a reliable signal for attribution. The techniques themselves are familiar, including stolen credentials, unpatched devices, SQL injection, and phishing. What changed is the economics, since reconnaissance, exploitation, and tool-building now get handed off to models that run in parallel at machine speed.

Autonomy lowers the cost side of an attacker’s math, Anthropic says, and makes previously unprofitable targets worth pursuing.

Malware that rebuilds itself when antivirus tools catch it

Anthropic tracks a Russian-speaking espionage actor as GTG-20006 that used a feedback loop. AI agents kept checking whether the malware in play was being flagged by common security products, and when an antivirus tool caught it, the agents rewrote and recompiled the malicious code on their own until it slipped past detection again.

That shifts the burden back onto defenders, Anthropic says, because writing new detection signatures no longer slows an attacker down if that attacker cycles through changes faster than new signatures can be rolled out.

More than 20 organizations were targeted, including government ministries, intelligence services, embassies, and defense contractors, with a focus on Ukraine and Europe. The drone supply chain came up repeatedly, and the actor stole a complete proprietary SDK for a drone vision system, among other things. Access sometimes ran through third parties, such as compromised hotel guest Wi-Fi providers whose guest devices were then loaded with malware, a method Microsoft described in July 2026 as CaptiveCrunch.

For clusters Anthropic attributes to the ShinyHunters collective (GTG-50014), industrial credential mining was the focus. One hacker downloaded 1.8 million Android apps, decompiled them, and searched for hardcoded secrets. Anthropic describes the approach as “vibe hacking,” where a human sets a rough goal and the model assesses the environment and iterates until the task is done. One of the hackers said he collected HackerOne bounties on top of extorting two companies.

Chinese labs route their own customers’ requests to Claude

On distillation, Anthropic identified attacks from seven more Chinese labs since its first disclosure in February. Distillation as a training method is legitimate, but Anthropic defines the illegitimate version as industrial-scale, covert campaigns that extract model capabilities without authorization, usually enabled by networks of fake accounts using stolen credit cards and API keys, routed through what it calls “transfer stations.”

The largest campaign ever measured is attributed to Alibaba’s Qwen lab (GTG-16005). A fixed prompt got Claude to write out its reasoning traces before answering, and the transcripts were processed into fine-tuning data for the Qwen 3.5, 3.6, and 3.7 models. The peak hit almost three million exchanges a day from more than 3,500 fraudulent accounts, totaling over 151 million exchanges between May and July 2026, mostly on agentic tasks and software development.

Stranger are the cases where labs relayed their own customers’ requests to Claude. Moonshot AI (GTG-16002) relayed nearly 300,000 customer requests to Anthropic over ten days across 5,380 fraudulent accounts, while users believed they were using a Kimi model. DeepSeek (GTG-16001) used strings to detect when requests came from harnesses like Claude Code, flagged those users, and routed selected ones to Claude Opus, more than 12.1 million exchanges in 14 days.

Among the rerouted requests, Anthropic found a user likely tied to the People’s Liberation Army who had CCTV archive footage analyzed for a single target, video from hundreds of cameras in Chengdu, including cameras outside PLA facilities. Through DeepSeek, Claude also received requests from an operator with live credentials for a database linked to the Russian Ministry of Defense, along with work on a case management system for a Chinese public security bureau that matches movement profiles against police records.

Xiaomi (GTG-16008) used Claude differently, storing requests and coding sessions from users of its own MiMo models and replaying those conversations through Claude to generate training data. Anthropic found no evidence that Claude’s responses were served directly to Xiaomi’s users. The relayed requests, however, contained personal data such as names, contact details, and company information for hundreds of people in at least a dozen languages.

Zhipu (known outside China as Z.ai) rotated through 273 accounts and pushed more than 770,000 exchanges over ten days through a CoT cleaner, a tool that automatically turns captured reasoning traces into usable training data. To train GLM-5.3 on cyber tasks, the lab first went after Anthropic’s Fable model but gave up after the cyber safeguards degraded its performance, then deliberately switched to models it judged to have weaker protections.

SenseTime bought transcripts from third parties, according to the report, so it did not obtain the captured Claude data itself but through an intermediary market. MiniMax ran its own proxy network through a shell company that offered only Anthropic and OpenAI models, no Chinese ones, not even its own.

Surveillance as the primary engineering workforce

In the surveillance chapter, Mali stands out. A single consultant used Claude as the primary engineering workforce for “Lakana 360,” a platform to monitor roughly 25 million SIM cards across all three national mobile carriers. It identifies people by voice across SIM swaps, flags users of encryption and VPNs, and links individuals to the national biometric civil registry.

Suspending the account interrupted only the development work, not the operation, since the platform runs on local models on-premises. Anthropic documents similar patterns with Iranian units that claim to have surveilled and profiled 6,388 Iranians within a year.

A first chapter on conventional weapons

On weapons, Anthropic documents its own cases for the first time. A cell in northern Yemen (GTG-87001) put Claude Code in the place of human software engineers for the guidance, navigation, and control software of three missile programs, including a multistage missile with a target range over 2,000 kilometers.

The actors ran several Claude instances in parallel and spread the work across sessions so that no single one revealed the intent. A test launch apparently failed, and within hours the actors returned to Claude to figure out the cause.

A second case (GTG-27005) likely involves freelance Russian actors who built an autonomous FPV kamikaze drone swarm, with a small language model onboard and terminal-phase targeting by camera. The platform was designed for autonomous lethal effect, and the onboard model could select targets of the “person” class and trigger detonation with no human in the loop. The image classifier was trained on captured Ukrainian combat footage, according to Anthropic.

A Chinese case (GTG-17002) involved a suite of roughly 16 modules for electronic warfare and the suppression of enemy air defenses. Midway through the project, the simulation’s default scenario switched to twelve targets in Taiwan.

Biology: Anthropic describes the limits of its own filters

The biology chapter is the most self-critical. Anthropic documents five anonymized cases involving working scientists where Claude assisted with potentially dangerous dual-use projects. In one case, the biosecurity classifier blocked a grant application for gain-of-function work on the chikungunya virus, planned at a military research institute.

The operator of the platform in use had built a fallback that routed requests Claude rejected to a competitor’s model, and Claude itself wrote most of the code for it, according to the report. Other projects ran largely unimpeded, such as drafting an application on immune evasion genes in orthopoxviruses.

The conclusion is that classifiers cannot both enable useful work and prevent harm, because a user’s intent in dual-use areas cannot be reliably detected. In response, Anthropic launched Claude Fable 5 with stricter safeguards for dual-use biology requests, and against distillation, the “preserved thinking” introduced with Fable 5.1 is meant to keep new API accounts from manipulating the context. The only safe path to frontier capabilities in biology, Anthropic says, runs through programs for verified users.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.


Subscribe now

Read the full article on The-Decoder.com
in AI
Reading Time: 7 mins read
0
0
23
VIEWS
Share on TwitterShare on Facebook

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now
ADVERTISEMENT

Related Posts

G7 Warns Quantum Threat Demands Action as Crypto Industry Weighs Fixes
AI

Morning Minute: AI Agents Cut BTC Quantum Attack Benchmark by 86%

3 hours ago
23
OpenAI floats a shared AI slowdown, takes it to Congress
AI

OpenAI floats a shared AI slowdown, takes it to Congress

3 hours ago
23
Albuquerque Bans Bitcoin ATMs, Giving Operators 45 Days to Remove Them
AI

Albuquerque Bans Bitcoin ATMs, Giving Operators 45 Days to Remove Them

5 hours ago
23

Comments

Please login to join discussion
ADVERTISEMENT

Latest News

  • All
  • Crypto
  • NFTs
  • Technology
  • Business
‘Return the Bitcoin’: Blockstream Draws Line After 4,000 BTC Hack
Crypto

‘Return the Bitcoin’: Blockstream Draws Line After 4,000 BTC Hack

Bitcoin.com News
by Bitcoin.com News
44 minutes ago
21
Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: ‘It Is Theft’
Crypto

Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: ‘It Is Theft’

Decrypt
by Decrypt
45 minutes ago
22
How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data
AI

How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

The Decoder
by The Decoder
1 hour ago
23
ZEC Dips Below $1,100 as Market Selloff Triggers Altcoin Pullback
Crypto

ZEC Dips Below $1,100 as Market Selloff Triggers Altcoin Pullback

Bitcoin.com News
by Bitcoin.com News
1 hour ago
22
AFTER 2049 Confirms Headliners Claptone and Crusy for Singapore Grand Prix Weekend Kickoff
Crypto

AFTER 2049 Confirms Headliners Claptone and Crusy for Singapore Grand Prix Weekend Kickoff

Bitcoin.com News
by Bitcoin.com News
2 hours ago
23
Technology

Does this AI comic make you laugh?

BBC News
by BBC News
2 hours ago
19
Load More
Next Post
Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: ‘It Is Theft’

Blockstream Refuses Ransom for Return of $47M in Bitcoin from Liquid Hack: 'It Is Theft'

ADVERTISEMENT

Follow Us

Categories

  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
Subscribe to our Newsletter

© 2022 Metaverse Media Group – The Metaverse Mecca

Privacy and Cookie Policy | Sitemap

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Sign Up
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Subscribe to our newsletter

Get the latest news & win monthly prizes

Subscribe to our newsletter

For the Latest News and Monthly Prize Giveaways

Join Now
Join Now